# Federal Contractor's Destruction of 96 Government Databases Marks Major Data Integrity Crisis
Former IT worker convicted of systematically wiping sensitive federal records in act of sabotage following termination
A 34-year-old Virginia man has been found guilty of one of the most brazen acts of government data destruction in recent federal history: the systematic deletion of approximately 96 government databases in February 2025, mere hours after being terminated from his contractor position. Sohaib Akhter, along with his twin brother Muneeb, executed a coordinated attack that compromised sensitive records across multiple federal agencies, raising serious questions about contractor vetting procedures and insider threat controls.
## The Incident: A Timeline of Sabotage
On February 18, 2025, both brothers were fired from their positions at a federal contractor company that maintained systems for over 45 U.S. government agencies, operating data servers in Ashburn, Virginia. The termination came after the company discovered Sohaib Akhter's prior felony conviction—a revelation that should have prevented their employment in the first place.
What happened next unfolded with alarming speed. Within hours of the remote termination meeting, the brothers used their still-active system access to launch a coordinated destruction campaign:
The scope of the destruction spanned multiple federal agencies and touched classified investigative materials—databases that federal investigators and law enforcement relied upon for active cases.
## Background: A Pattern of Federal Access Abuse
Understanding this case requires examining the brothers' history. In 2016, Sohaib and Muneeb Akhter were convicted of breaking into U.S. State Department systems without authorization and stealing personal information belonging to dozens of colleagues and a federal law enforcement agent investigating them. They served their sentences and were released.
Despite these felony convictions—which should have permanently disqualified them from federal contractor work—both brothers were later hired by a contractor company with access to sensitive government infrastructure. This hiring decision represents a critical failure in the federal contractor vetting process, one with consequences that extend far beyond the individual case.
## Technical Details: The Method of Destruction
Court documents reveal the technical sophistication of the attack, demonstrating knowledge of database management systems and system administration procedures:
| Action | Technical Purpose | Impact |
|--------|------------------|--------|
| Write-protect databases | Prevent recovery/modification | Ensured permanent deletion |
| Mass database deletion | Remove evidence at scale | ~96 databases compromised |
| Log clearing commands | Remove audit trails | Destroyed accountability records |
| Credential abuse | Maintain access after termination | Extended window for sabotage |
| Device wiping | Destroy local evidence | Eliminated traces on hardware |
The fact that the brothers sought AI assistance for log clearing indicates a troubling trend: bad actors are rapidly integrating large language models into their attack workflows. They recognized that AI could provide specific technical guidance for covering their tracks—a threat vector that security teams are only beginning to understand.
## Scope of Damage: 96 Databases Across Federal Agencies
The scale of this breach cannot be overstated. The destroyed databases included:
For context, 96 databases is not a small subset—it represents a systematic, comprehensive attempt to eliminate records. Each database may contain hundreds of thousands or millions of individual records, affecting countless investigations, policy decisions, and public transparency requirements.
## Legal Consequences and Ongoing Prosecution
Sohaib Akhter was convicted on charges related to unauthorized computer access and destruction of records. He faces sentencing on September 9, 2026, with a maximum penalty of 21 years in prison.
His brother, Muneeb Akhter, faces even more severe charges and penalties:
The Justice Department's prosecution strategy reflects the seriousness with which federal authorities are treating this case. As Jennifer L. Fain, Inspector General of the FDIC-OIG, stated: "The deliberate deletion of databases containing sensitive government information and the subsequent attempts to conceal that criminal activity demonstrated a blatant disregard for the security and integrity of federal information systems."
## Systemic Implications: Contractor Vetting Failures
The most troubling aspect of this case is that it was preventable. Sohaib Akhter's 2016 felony conviction should have automatically disqualified him from federal contractor positions. The fact that both brothers were hired—and rehired—despite their criminal histories points to systemic failures in the vetting process:
These failures are not unique to this contractor. Across the federal government, thousands of contractors maintain access to sensitive systems. If this organization could miss something this obvious, it raises questions about how many other high-risk individuals may have access to federal infrastructure.
## HackWire Analysis
This case exemplifies a dangerous pattern in federal cybersecurity: the conviction that technology controls alone can secure systems, while human and process controls atrophy. The Akhter brothers possessed something more valuable than passwords—they had legitimacy. A contractor ID, system access, and the routine authorization to touch databases meant nobody questioned them when they logged in on February 18th. Until, of course, it was too late.
What's particularly striking is the *speed* of the attack. Within hours of termination, 96 databases were gone. This suggests that immediate access revocation didn't happen—or was circumvented. It also suggests that no real-time monitoring of mass deletion activity triggered alerts. In a well-designed system, deleting 96 databases should generate alerts that wake security teams at 3 AM.
The AI query adds a new wrinkle that most incident response teams aren't equipped to handle. The brothers didn't write custom log-clearing scripts; they asked a chatbot. This is a preview of the insider threat landscape: attackers are outsourcing technical knowledge to language models, making it easier for less sophisticated bad actors to execute sophisticated attacks. Log clearing has always been a concern, but when the attacker can ask ChatGPT "how do I clear audit logs on [database system]" and get usable answers in seconds, the threat surface expands.
The federal contracting ecosystem remains fractured across dozens of agencies with inconsistent security standards. One agency's "thorough" vetting may be another's "checkbox compliance." Until there's a unified, real-time database of contractor disqualifications that actually prevents hiring, we'll see this pattern repeat. The Akhter brothers had already violated the system once and served time. They shouldn't have been in the building.
— HackWire Editorial
## Recommendations for Federal Agencies and Contractors
Organizations managing federal systems should implement immediate controls:
1. Real-time access revocation upon termination, not delayed credential cleanup
2. Continuous vetting of contractors against updated criminal databases
3. Monitoring for mass data deletion with automated alerts
4. Audit trail redundancy preventing single-point deletion of logs
5. Immutable backup systems for critical databases, separated from production environments
6. Insider threat training focusing on contractors, not just employees
7. AI guardrails to prevent LLMs from providing specific system administration attack guidance
## Related Coverage